A question about Auto-Enrolment
can please me following question, thanks
i reading following article
https://technet.microsoft.com/en-us/library/cc778245(v=ws.10).aspx
at first glance seemed contradict (i think know answer want check hence post)
the article says
- on issuance requirements tab of selected certificate template, selecting this number of authorized signatures , making value greater 1 disables subject autoenrollment based on template.
- on issuance requirements tab of selected certificate template, selecting this number of authorized signatures , setting value 1 requires requester sign request private key valid certificate in certificate store. certificate must contain application , issuance policies specified in application policy , issuance policies lists on same tab. if appropriate certificate exists in requester's certificate store, autoenrollment signs request certificate's private key , obtains , installs requested certificate automatically.
so when comes “the number of authorised signatures” first bullet point states ‘disable’ auto-enrolment second bullet point says “obtains , installs requested certificate automatically”
what believe saying if have ‘code signing’ certificate appropriate ‘application policies (eku)’ , ‘issuance policies’ in code signing cert (e.g. match requirements of template). long code signing cert in x509 store on pc, can auto-enrol , if not have has code signing cert sign csr
is correct?
if x509 store should code signing cert be in localmachine\personal or currentuser\personal or other?
thanks all
ernie
> ku still require 'digitalsignature'
no, doesn't require. think this: when create certificate request efs, example, keyusage extension set keyencipherment. @ same time, key used sign reuqest authenticate data. specific case key usage doesn't matter @ all.
> correct please?
generally understanding correct, not in given case.
vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki.codeplex.com
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.
Windows Server > Security
Comments
Post a Comment